Getting Data In

splunk upgrade from 7.3.3 to 8.0.0 failed (Could not create path D:\splunk\data\index\_metrics\db appearing in indexes.conf: 5 )

Loves-to-Learn

Hi, anyone know how to solve this problem?

C:\Users\AppData\Local\temp\splunk.log
In the log file is shown :

Could not create path D:\splunk\data\index_metrics\db appearing in indexes.conf: 5
Validating databases (splunk valiadated) failed with code '1'

as we have tried to use Admin account already and can access to this folder D:\splunk\data\index\_metrics.
but we cannot upgrade successfully.

system environment:
Splunk 7.3.3
Windows Server 2012 R2

Tags (3)
0 Karma

Esteemed Legend

This is a permissions problem: Splunk cannot create that directory and it MUST in order to run. You can either manually create or give the user that Splunk is running as the permission to create it.

0 Karma

Communicator

Hi,

can you check under which user splunk service is running? By default it is system. This user also needs to have read/write/execute permission on the folder D:\splunk\data\index_metrics\

Just a friendly tip: I suggest you migrate your splunk environment to linux. Since we have done it, our life is much easier.

0 Karma

Loves-to-Learn

Do you know which user for D:\splunk\data\index\_metrics\?
As currently, we cannot see the owner.

https://imgur.com/ru47Xw8
https://imgur.com/ru47Xw8
https://imgur.com/Wxxa6Rw

0 Karma

Loves-to-Learn

system user is running splunkd service.
For D:\splunk\data\index\_metrics\, it is read only and it shows that You do not have permission to view this object's security properties, even as an administrator user.

0 Karma

Communicator

@jerjer951109 I see that can be your problem... Try taking over ownership of the folder with your admin account and then you will be able to change the permissions.

0 Karma

Splunk Employee
Splunk Employee

Hi @jerjer951109 ,

Where are you seeing that message?

Cheers,

- Jo.

0 Karma

Loves-to-Learn

C:\Users\AppData\Local\temp\splunk.log

0 Karma

Loves-to-Learn

i upgrade using splunk-8.0.0-x64.msi but failed
then i checked log C:\Users\AppData\Local\temp\splunk.log and see this error

0 Karma

Loves-to-Learn

OS: Windows server 2012

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!